Deployment Architecture

Why am I getting a 500 Internal Server Error immediately after logging into my external IP address on Ubuntu?

krypterro
Explorer

On a new install, I am getting a 500 Internal Server Error immediately after logging into my external IP address at port 8000 over http. Once that happens, Splunk errors out, and I can't try to log in again until I restart Splunk. But when I check ./splunk status it appears to be fine. This is on a fresh Ubuntu 16 server on a VPS. I have tried all the reasonably applicable solutions posted here with no success. Any suggestions?

0 Karma
1 Solution

krypterro
Explorer

Nevermind, forgot to restart. That fixed the problem, thanks.

View solution in original post

0 Karma

sudosplunk
Motivator

Hi there,

Please look at splunkd.log file (located at $SPLUNK_HOME/var/log/splunk) for errors or warnings and provide some data to further assist you.

0 Karma

krypterro
Explorer

Nevermind, forgot to restart. That fixed the problem, thanks.

0 Karma

renjith_nair
Legend

So what was the last change you did before restart to fix the issue?

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

renjith_nair
Legend

Worth to check mgmtHostPort = <IP:port> in your web.conf. Normally this error happens when your web is not able to connect to splunkd.

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

krypterro
Explorer

I changed it from: [mgmtHostPort = 127.0.0.1:8089] to the external IP address, with no change. Is there something special that must be done to access the web interface remotely as opposed to via localhost, which appears to be the default configuration?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...